cleantalk
Vulnerabilities and Security Researches

Contact Form by WPForms – Drag & Drop Form Builder for WordPress, 968181b8559f062008e22f59da5ad30471dec097

Published on
Sep 18, 2018
Research Description
WPForms &#8211; Easy Form Builder for WordPress &#8211; Contact Forms, Payment Forms, Surveys, &amp; More [wpforms-lite] < 1.4.8 Contact Form by WPForms – Drag & Drop Form Builder for WordPress <= 1.4.7.2 - Stored Cross-Site Scripting The Contact Form by WPForms – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the tab parameter in versions up to, and including 1.4.7. This makes it possible for lower-privileged attackers to inject arbitrary web scripts in administrative pages that execute whenever a user accesses the page with the stored web scripts.
Affected versions
max 1.4.8.
Status
vulnerable